Four Microsoft security patches due next week
Microsoft plans to fix critical bugs in its Word, Publisher and Jet database
software next week.
The software vendor also plans to release a less-critical update for its antivirus
products, fixing a flaw that attackers could use to launch a denial of service
(DoS) attack against products such as Windows Live OneCare and Microsoft Forefront
Security.
The updates will be released Tuesday, the day set aside for Microsoft's monthly
set of security patches. Microsoft provided some early details on the patches
Thursday, in a note
on its Web site.
Microsoft considers flaws to be critical when they could be exploited by attackers
in order to run unauthorized software on a victim's system.
Although Microsoft's note does not describe the bugs in detail, it looks like
the company is planning to fix a known bug in the Jet database engine, which
was disclosed in late March. Attackers had figured out a new way to launch a
malicious Jet file using Microsoft Word, Microsoft warned in a blog
posting.
Jet files, which have a .mdb extension, are typically blocked by Outlook, but
"attackers have figured out a way to work around the mitigations built
into Outlook," Microsoft said in its post.
The Jet flaw affects Windows XP, 2000 and Server 2003 Service Pack 1.
The Word flaw is rated critical for both Windows and Mac users.
Although rated only "moderate," the DoS bug in Microsoft's security
products is also a cause for concern. It affects many Microsoft security products
including OneCare, Antigen, Windows Defender, Standalone System Sweeper and
several Forefront Security products.
IDG News Service
Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.
Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.
Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.







